Bits of Gold, Israel’s largest regulated cryptocurrency broker, is investigating a potential leak of personal data that may have affected as many as 200,000 customers, according to Israeli outlet Calcalist. The company holds one of nine active virtual asset service provider licenses issued by Israel’s Capital Market Authority and serves roughly 300,000 registered customers.
The exposed information reportedly includes full names, national ID numbers, email addresses, IP addresses and phone numbers. Bits of Gold has said that funds, coins, account passwords, ID document copies and credit card details were not affected by the incident.
Part of a Wider Software Supply-Chain Incident
The company’s assessment is that it was not directly targeted. Instead, the breach traces back to a security failure at a third-party software vendor whose systems Bits of Gold relies on for a support and data-analysis tool — a breach that reportedly affected other companies globally as well, not just Bits of Gold. Upon identifying unauthorized access to that support system, the company blocked access to it and disconnected it from its underlying data sources.
Response Underway
Bits of Gold said its security team has begun a comprehensive review of the incident, working alongside an outside firm that specializes in cyber incident investigation and response, and that it has notified the relevant Israeli authorities. As of the initial disclosure, the company had not confirmed the exact number of customers affected or named the third-party vendor whose systems were compromised.
Related: DefiLlama Delayed Its App Launch to Wait Out Apple Store Impostors
A Regulated Broker Is Not Immune to Vendor Risk
The incident underscores a distinction that regulatory licensing doesn’t fully address: a VASP license covers how a firm handles customer funds and complies with financial rules, not the security posture of every third-party vendor it plugs into its support stack. Crypto platforms of all kinds — from mobile app publishers to hardware wallet makers — have increasingly found that their weakest security link sits not in their own core product, but in the ordinary customer-service and analytics tooling wrapped around it.